Debian Security Advisory DSA 1094-1 (gforge)

Summary
The remote host is missing an update to gforge announced via advisory DSA 1094-1. Joxean Koret discovered several cross-site scripting vulnerabilities in Gforge, an online collaboration suite for software development, which allow injection of web script code. The old stable distribution (woody) does not contain gforge packages.
Solution
For the stable distribution (sarge) this problem has been fixed in version 3.1-31sarge1. For the unstable distribution (sid) this problem has been fixed in version 3.1-31sarge1. We recommend that you upgrade your gforge package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201094-1